Concerns about password managers and browser extensions

Correct me if I am wrong, but I see following issues with password managers:

  1. Are you sure that your password manager generates cryptographically secure passwords? I mean truly random password generator? Or pseudorandom?
  2. As I know, if pseudorandom fenerator used, anyone, if they got certain amount of such passwords predict (even approximately) other passwords, right?

And completely separate concern is browser extensions. What if browser got compromised (ex 0-day vuln)? This means that extension data in UNLOCKED state cud possibly leak. Yes, I know that you will tell to use secure browsers etc, but shit happens, right?

So for now I have following opinion:

  • Slightly modify generated password before saving in your password manager (to make it really random)
  • NEVER use extensions?

Correct me if I am wrong.

a truly random password? no. this site provides one, but it is an website so you cant trust it.

could you clarify your concern again please? i dont understand this part.

short answer: yes, shit happens. long answers: e.g. bitwarden lives in an protected space so it isnt too easy to achieve that, but when it comes to zero days: everything can happen.

this doesnt really help and would probably make it worse. even though computers cant generated truly random passwords, humans cant either and are even worse.

depends on your threat model, but yes theoretically its safer to never use any extensions regarding password managers.

I thought extension’s prevent items being copied to the clipboard. Without the extension how does one prevent items being copied to the clipboard?

KeePassXC has an autotype feature, but it seems like it requires X11 so I’m skeptical of its security

This seems similar to Universal Autofill in 1Password 8.